Depzilla
Back to depzilla.com

Executive / Strategic

Enterprise Risk Management

The risk that hurts you is the one nobody traced across the gaps.

Strategic, operational, and project risk in a single connected register.

The problem

Risk is usually managed in fragments: strategic risk in the board pack, operational risk in the department register, project risk in a spreadsheet on someone's desktop. Nothing connects — so the exposure that matters sits in the space between them, unseen until it lands.

Why exposure hides

Most ERM systems are a register with a workflow bolted on. They store risk; they don't reason about it — so exposure sits in a spreadsheet until someone remembers to look.

What Depzilla does

Depzilla puts a SuperCrew agent in the Enterprise Risk Officer's chair, over a register that runs the whole org hierarchy — enterprise, business unit, department and project — as one connected model. It correlates exposure across units, flags controls that have gone quiet, connects a delayed project to the enterprise consequence nobody else has traced, drafts each reassessment from what actually changed, and writes the committee narrative from the data. It proposes; a human approves before anything reaches the register. And because ERM shares a backbone with Strategy Management, every exposure is attached to the objective it endangers.

Features and capability

  • One register, the whole hierarchy — enterprise, business-unit, department and project risk in a single connected model, scoped by org subtree so a unit sees its own and the board sees the roll-up

  • Inherent to residual to target — three full scoring snapshots where most platforms stop at two, and the target stage carries the improvement plan that gets you there

  • Residual earned, not asserted — control effectiveness derived as (inherent − residual) ÷ inherent, so residual comes from the controls actually mapped and tested; an override is allowed, flagged and audited

  • Control library with real testing — preventive, detective and corrective controls mapped many-to-many to risks, with attestation campaigns and captured evidence behind the effectiveness rating

  • Treatments that cost something — reduce, transfer, accept or avoid — each with an owner, a KPI, a budget and a timeline, tracked through to overdue rather than logged and forgotten

  • Key risk indicators with breach alerts — thresholds per indicator, values fed by hand or by API, breach state computed continuously and the risk owner told when it trips

  • Appetite as a first-class object — tolerance bands per category and multiple appetite profiles, with every breach flagged on the register instead of discovered in a review

  • Configured, never coded — classifications, impact axes, matrix size, band thresholds and treatment strategies are all tenant configuration — and config is versioned, so changing a matrix never silently rewrites last year's scores

  • Audit-grade trend history — every assessment is a timestamped snapshot, so the heat map replays a risk's migration over time instead of only showing you today

  • Framework and control mapping — map risks and controls onto your own framework structure, reuse one control across many, and see the coverage gaps it leaves

  • AI that proposes, never posts — reassessments drafted from what actually changed, emerging risks surfaced for triage, the committee narrative written from live data — and a human approves before any of it reaches the register

  • Committee-ready reporting and import — board and steering-committee briefs generated from live data, and an Excel/CSV import that migrates the register you already keep in a spreadsheet

See it in action

At a glance · Click the screen to view it full size

Risk stops being a parallel universe — and starts escalating when it matters, not when the calendar says so.

See what this looks like in your operation.

Book a free Operations Assessment — a 30-minute working session where we map where your operations leak time and money, and what a fix would look like.

30 minutes · No pitch · No obligation